当前位置:网站首页>A mining of edu certificate station
A mining of edu certificate station
2022-07-04 23:10:00 【Hetian network security laboratory】
Preface
lately edusrc New certificate , This cannot be arranged for him .
Set goals
Information collection without words , Open it directly fofa, Use the syntax title="XXX university ", Found a system

See the login box , Maybe everyone will blow up the weak password first , Maybe my face is black , I have never been able to burst out in this way , So I prefer to test unauthorized access , Here I casually input an account number and password

Return to grab the return package of this interface , Back in the bag 500

Here I change it to 200 , Can enter the system , But there is no data information

And then I just F12 View the source code , Found a route ,/EmployeeManager, Splice it behind the website
visit

【---- Help network security learn , All the following learning materials are free ! Add weix:yj009991, remarks “ csdn ” obtain !】
① Thinking map of the growth path of Network Security Learning
② 60+ Network security classic common toolkit
③ 100+SRC Vulnerability analysis report
④ 150+ Network security attack and defense technology ebook
⑤ The most authoritative CISSP Certification test guide + Question bank
⑥ super 1800 page CTF Practical skills manual
Direct unauthorized access , Moderately dangerous , I originally wanted to submit it manually , But look at the certificate exchange conditions , Get two medium risks , It's not to embarrass me , There is no way to continue working overtime , So I used the user name and password I just got to log in

There is a personal commitment after logging in , You need to agree to the next step , Click OK to capture the package


The interface returns the user's ID card and password , And then EmployeeID=000005 Change to 000006


Another level of ultra vires , Leaked user sensitive information , Moderate risk should be stable , Then I noticed that this system distinguishes between the administrator and the ordinary user , A front-end can choose the role type to log in , Then I thought about whether I could log in with the account and password of ordinary users , Then exceed the authority of the administrator , Capture packets when logging in

Intercept the return packets of this interface

hold QX Change to administrator , And then put the bag

You can see that you have overstepped your authority and become an administrator
end
Are very conventional loopholes , The most important thing is to be careful .
More range experiments 、 Network security learning materials , Please click here >>
https://www.hetianlab.com
边栏推荐
- mamp下缺少pcntl扩展的解决办法,Fatal error: Call to undefined function pcntl_signal()
- The difference between Max and greatest in SQL
- Excel 快捷键-随时补充
- Redis入门完整教程:GEO
- Advanced area a of attack and defense world misc Masters_ good_ idea
- 【机器学习】手写数字识别
- 【图论】拓扑排序
- Advantages of Alibaba cloud international CDN
- A complete tutorial for getting started with redis: redis usage scenarios
- Explanation of bitwise operators
猜你喜欢

Redis: redis message publishing and subscription (understand)
![P2181 对角线和P1030 [NOIP2001 普及组] 求先序排列](/img/79/36c46421bce08284838f68f11cda29.png)
P2181 对角线和P1030 [NOIP2001 普及组] 求先序排列

【剑指offer】1-5题

Redis入门完整教程:键管理

Sobel filter

SPH中的粒子初始排列问题(两张图解决)

Redis入门完整教程:初识Redis

Network namespace

A complete tutorial for getting started with redis: redis shell

D3.js+Three. JS data visualization 3D Earth JS special effect
随机推荐
cout/cerr/clog的区别
Sword finger offer 68 - I. nearest common ancestor of binary search tree
mamp下缺少pcntl扩展的解决办法,Fatal error: Call to undefined function pcntl_signal()
MariaDB的Galera集群应用场景--数据库多主多活
初试为锐捷交换机跨设备型号升级版本(以RG-S2952G-E为例)
EditPlus--用法--快捷键/配置/背景色/字体大小
Redis入门完整教程:HyperLogLog
Sobel filter
[Taichi] change pbf2d (position based fluid simulation) of Taiji to pbf3d with minimal modification
Sword finger offer 65 Add without adding, subtracting, multiplying, dividing
【ODX Studio编辑PDX】-0.3-如何删除/修改Variant变体中继承的(Inherited)元素
On-off and on-off of quality system construction
The difference between Max and greatest in SQL
The small program vant tab component solves the problem of too much text and incomplete display
Attack and defense world misc advanced zone 2017_ Dating_ in_ Singapore
Photoshop批量给不同的图片添加不同的编号
Google Earth engine (GEE) -- take modis/006/mcd19a2 as an example to batch download the daily mean, maximum, minimum, standard deviation, statistical analysis of variance and CSV download of daily AOD
A complete tutorial for getting started with redis: redis shell
Advanced area a of attack and defense world misc Masters_ good_ idea
colResizable. JS auto adjust table width plug-in